A few hours ago we’ve been notified of a serious bug in Phusion Passenger 4. If the web app does not supply a Date header, then Phusion Passenger normally adds one in order to comply to the HTTP standard. Unfortunately due to the use of the wrong date format string, December 30 2013 and December 31 2013 are formatted as December 30 2014 and December 31 2014, respectively. As a result, cookies that expire before 2014 would expire on December 30 2013 and December 31 2013. Details can be found at